CVE-2023-33792: XSS
A stored cross-site scripting (XSS) vulnerability in the Create Site Groups (/dcim/site-groups/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-33792.
What is the severity rating of CVE-2023-33792?
CVE-2023-33792 has a severity rating of medium (5.4).
What is the affected software?
The affected software is Netbox v3.5.1.
How does the vulnerability in CVE-2023-33792 work?
CVE-2023-33792 is a stored cross-site scripting (XSS) vulnerability in the Create Site Groups function of Netbox v3.5.1 that allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Is there a fix available for CVE-2023-33792?
As of now, there is no official fix available for CVE-2023-33792. It is recommended to follow the advisory or updates from the Netbox Project for any patches or mitigations.